PatchesMedium

WordPress 7.1.3 fixes seven security flaws, including XSS and SQL injection bugs

The WordPress project released version 7.1.3 on October 6 with seven security fixes and four bug fixes, urging site owners to update immediately.

WordPress 7.1.3 fixes seven security flaws, including XSS and SQL injection bugs

At a glance

  • WordPress 7.1.3 was released on October 6 with seven security fixes and four bug fixes.
  • Fixes cover stored XSS on the comments admin page, a second-order SQL injection in WXR export and a private-comment leak.
  • Patchstack says most issues require a logged-in user or an admin action and calls it not a drop-everything emergency.
  • Sites with automatic background updates receive the release automatically; fixes are being backported to older branches.

The WordPress project released WordPress 7.1.3 on October 6, a maintenance and security update that fixes seven security vulnerabilities and four other bugs in the content management system's core. "Because this is a security release, it is recommended that you update your sites immediately," the project said in its announcement.

What happened

According to the WordPress.org announcement, the seven security issues fixed in 7.1.3 were reported by several researchers and organizations, including Trail of Bits, Anthropic, Patchstack and members of the WordPress security team. The release was led by Jake Spurlock, and the project said more than 40 community members contributed to it.

WordPress security company Patchstack, whose researcher reported one of the issues, published a breakdown of the fixes. Its assessment is measured: "Update as soon as you can, but this isn't a drop-everything emergency," the company wrote, noting that most of the bugs require a logged-in account or interaction from a site administrator or moderator.

Technical details

Based on the WordPress.org and Patchstack descriptions, the security fixes cover:

  • A stored XSS issue on the Comments administration page, triggered when a moderator clicks a malicious link in a pending comment (reported by Trail of Bits).
  • A denial-of-service bug in WP_Http::make_absolute_url() that could cause an infinite loop; Patchstack says it requires a Contributor-level account.
  • A second-order SQL injection in the WXR export feature, which Patchstack says depends on an administrator running an export together with manipulated metadata.
  • An authorization flaw that let Author-level users make posts sticky.
  • Disclosure of comments on private and unpublished posts through feeds, which Patchstack says needs no authentication.
  • An XSS issue involving Imgur embeds; Patchstack says Imgur was removed from the trusted oEmbed provider list as part of the fix.
  • A hook parameter issue that could cause action name collisions, which Patchstack describes as plugin-dependent.

The announcement does not list CVE identifiers for the individual fixes.

Who is affected

All sites running WordPress versions before 7.1.3 are affected to some degree. The project says security fixes are being backported to eligible older branches as far back as 4.7, although only the latest version is actively supported. At the time of Patchstack's writing, backports had been released for branches down to 6.6, with older branches still pending.

What to do

Site owners should update to WordPress 7.1.3 from the dashboard or WordPress.org. Sites with automatic background updates enabled will receive the release on their own, but administrators should confirm the update was applied. Patchstack also recommends reviewing which users hold Contributor or higher roles, since several of the fixed issues depend on such accounts.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.